Quiz Entry - updated: 2026.09.28
How do architecture, IT and information security work together around ISO 27001, and what does each contribute?
Architecture designs the plan and demands a secure construction; the IT department builds and operates the cyber system following the plan; information/IT security sets requirements, using ISO 27001 as its template, and demands that the system is securely manageable. The goal is that these requirements meet without conflict.
| Role | Does | Its requirement |
|---|---|---|
| Architecture | Designs the plan | Secure construction |
| IT department | (1) Builds and (2) operates the cyber system, following the plan | |
| Information / IT security | Sets requirements for IT, using ISO 27001 as a general framework | Securely manageable |
The system has to satisfy both requirements at once. A design that is secure on paper but cannot be operated according to the ISMS processes fails, and so does a well-managed system built on an insecure construction. The architect's job includes making the two meet without conflict.